spencer's Avatar

spencer

@bsky.ethicalthreat.com

πŸ› οΈ Former Sysadmin, now Pentester | Microsoft MVP | Helping IT teams make their environment harder to attack Pentesting -> SecurIT360 Podcast -> CyberThreatPOV Active Directory Security Resources for IT Admins πŸ‘‡ https://go.spenceralessi.com/adsecurity

3,674
Followers
112
Following
1,174
Posts
09.11.2024
Joined
Posts Following

Latest posts by spencer @bsky.ethicalthreat.com

Preview
Developer machines are higher risk than Domain Admin machines

From an internal threat perspective, developer machines are as good as getting Domain Admin, and many times even more "lucrative" from an attack pov

They have the keys and typically much less oversight.

youtube.com/clip/UgkxqDZ...

12.03.2026 13:37 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Respect the game hah

12.03.2026 01:43 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Wow that’s… incredible hahah

12.03.2026 01:42 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

Haha that’s so good

12.03.2026 01:42 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Right! Hah

11.03.2026 18:49 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Cat wallpaper

11.03.2026 18:49 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Haha did you get the donuts tho?

11.03.2026 18:49 πŸ‘ 2 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

Yes, you should lock your computer when you get up and walk away while at the office. No, you're not gonna get hacked in the 3 minutes that you're gone from your desk getting some water. YMMV

11.03.2026 18:14 πŸ‘ 1 πŸ” 0 πŸ’¬ 4 πŸ“Œ 0

You should speak to your AI so it can understand the intent and inflection in your voice. You really want it to know when you're ticked off because it's creating bugs in your code.

11.03.2026 16:22 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Imagine if one day we don’t see any more Kerberoastable domain admin accounts. It would be something right…

11.03.2026 14:55 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Tell me you’ve worked in IT without telling me you’ve worked in IT.

I’ll go first…

Did you try turning it off and back on again?

11.03.2026 13:29 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

Y’all are focusing on the wrong thing. organizations don’t get better by automating pentesting and eliminating pentesting jobs.

Organizations get better by making their systems more secure and resilient.

Great, you found 4000 vulnerabilities in half the time, IT admin still need to fix that stuff

10.03.2026 18:34 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

IT admin skills are absolutely foundational to cybersecurity. How can you get a degree in cybersecurity and not ever see a UAC prompt before?!

10.03.2026 16:52 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

While no AI isn’t replacing pentesters just yet, I do believe it’s changing the game drastically. It’s forcing low quality pentesting to raise the bar.

It’s also a signal of what’s to come. But also, I think in many ways the β€œmarket” will decide if these ai pentesting platforms have value or not.

10.03.2026 14:36 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
AI is going to k*ll pentesting jobs!!
AI is going to k*ll pentesting jobs!! Follow me on X: @techspence

The advancements in AI this last 12 months have been staggering…

But AI will only take your pentesting job if all you did was run a vulnerability scan and ship the report.

Pentesting, a professional pentest, is more than running tools

youtube.com/shorts/joYT9...

10.03.2026 12:52 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

Smart

10.03.2026 02:12 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Haha exactly

10.03.2026 02:11 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

As a defender, I want the advantage. I want my environment to be hostile territory to adversaries.

I want them to know…
that I know
that they know
I see them.

Get wrecked.

09.03.2026 18:14 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

How to get people to talk about your stuff.

Make something that intersects with what people want and something that solves a deeply painful problem.

Then make it really really good.

09.03.2026 16:46 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Whenever there’s an IT issue it’s always this (in order)…

It’s not plugged in
DNS

09.03.2026 14:34 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

I don’t think you can have a true appreciation for IT support unless you’ve lived in and experienced it yourself

09.03.2026 13:13 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

The best way to learn how secure something is the first use it then have to administer it οΏΌ

06.03.2026 19:12 πŸ‘ 3 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Part of what makes you a good pentester is you know what rocks to turn over

06.03.2026 17:43 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Would you rather…

Have to secure Wordpress or OpenClaw?

(for the rest of your life if you had one singular job and this was it)

06.03.2026 15:26 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

So who has interesting cybersecurity or IT-related use cases for openclaw they are playing around with? I wanna see some fun stuff…

06.03.2026 14:09 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Sure but I’d argue in this example, not accidentally configuring a template for ESC1 should be within their purview

06.03.2026 13:08 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

Learn Active Directory and you’ll never work another day in your life….

You’ll work every day πŸ€ͺπŸ˜‚

05.03.2026 19:09 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

If you’re an IT admin and you want upward career progression and you have any length of time left in your career, beginning to poke at these AI platforms and becoming comfortable with them is crucial.

Not to be an expert but so you know what’s coming.

05.03.2026 17:37 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

I personally think IT admin cybersecurity skills should go beyond the basics. If you manage ADCS you should be familiar with certificate abuse for example

05.03.2026 16:59 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

Badum chhhh hah

05.03.2026 16:58 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0